feat(sharing): make going online opt-in, and show what it unlocks

Tane dialled its four default relays at launch, before anyone had asked
for anything — an F-Droid reviewer spotted it, and they were right. The
seed book needs no network at all, so the app should not have one until
the person joins the sharing side.

- SocialSettings gains a three-state `sharingEnabled`. `null` means
  "never asked", which is what lets `migrateSharingEnabled` keep an
  existing install exactly as it was: anyone past the intro was on a
  build that connected at launch, so they keep messaging, device sync
  and offer alerts. A fresh install starts fully offline.
- bootstrap only starts the shared connection when sharing is on. The
  inbox/sync/plantaré/alert listeners are untouched: they react to a
  session, and none arrives.
- SharingSwitch is the single place that moves the stored choice, the
  live connection and the flag the UI listens to, so they cannot drift.
- Agreeing to the community rules is the opt-in — one consent surface,
  reached from the market or from the drawer's invitation.
- SocialConnection.start is now idempotent and gains stop(), so turning
  sharing off goes offline immediately instead of at the next launch.
- The social drawer entries stay visible but padlocked while sharing is
  off; tapping one explains what wakes up and offers to join. Hiding
  them would have kept the tool a secret. "Coming soon" is gone for
  good — everything it labelled is built.

Covered by tests for the migration in both directions, start/stop
lifecycle, the gate turning sharing on, the invitation, and the drawer
in all three states (no social layer / off / on).
This commit is contained in:
vjrj 2026-07-25 16:47:56 +02:00
parent 62123582f5
commit fed0e8200e
35 changed files with 926 additions and 173 deletions

View file

@ -23,6 +23,7 @@ import 'services/social_account_store.dart';
import 'services/social_connection.dart';
import 'services/social_service.dart';
import 'services/social_settings.dart';
import 'services/sharing_switch.dart';
import 'state/inventory_cubit.dart';
import 'state/variety_detail_cubit.dart';
import 'ui/about_screen.dart';
@ -70,6 +71,7 @@ class TaneApp extends StatelessWidget {
this.notifications,
this.showIntro = false,
this.autoBackup,
SharingSwitch? sharing,
super.key,
}) : _router = _buildRouter(
repository,
@ -87,6 +89,17 @@ class TaneApp extends StatelessWidget {
savedSearches,
socialAccounts,
inbox,
// `bootstrap` passes the real switch, holding the person's stored
// answer. A widget test that doesn't care gets one already on, so
// screens behave as they did before sharing became opt-in.
sharing ??
(socialSettings == null
? null
: SharingSwitch(
settings: socialSettings,
connection: connection,
enabled: true,
)),
) {
// A tapped message notification opens that peer's chat. Wired here because
// the router only exists now; taps only happen while the app is foreground,
@ -161,14 +174,17 @@ class TaneApp extends StatelessWidget {
SavedSearchesStore? savedSearches,
SocialAccountStore? socialAccounts,
InboxService? inbox,
SharingSwitch? sharing,
) {
return GoRouter(
initialLocation: showIntro ? '/intro' : '/',
routes: [
GoRoute(
path: '/',
// A null switch means there is no social layer at all: the market card
// and the social drawer entries aren't drawn.
builder: (context, state) =>
HomeScreen(marketEnabled: social != null),
HomeScreen(sharing: sharing, onboarding: onboarding),
),
if (social != null && socialSettings != null && connection != null)
GoRoute(
@ -181,6 +197,7 @@ class TaneApp extends StatelessWidget {
outbox: outbox,
onboarding: onboarding,
savedSearches: savedSearches,
sharing: sharing,
),
),
if (social != null && connection != null)